Impact
An unauthenticated attacker on the same OSPFv3 broadcast domain can send specially crafted packets that cause the OSPFv3 agent to crash. The crash results in the loss of all OSPFv3 adjacencies on the affected device and may disrupt routing across the broader OSPF domain until the agent recovers. The vulnerability is tied to improper handling of input in the OSPFv3 protocol stack (CWE-617) and carries a CVSS score of 7, indicating a medium-high impact.
Affected Systems
The flaw affects Arista Networks EOS releases in the 4.36.x train from version 4.36.2F onward, in the 4.35.x train from 4.35.6M onward, in the 4.34.x train from 4.34.8M onward, and in the 4.33.x train from 4.33.10M onward. All earlier EOS versions in these trains are vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low but non-zero probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is a local network actor in the same OSPFv3 broadcast domain who can send crafted packets without authentication. No evidence of active exploitation in the wild has been reported; however, the crash can cause significant routing disruption in the affected network.
OpenCVE Enrichment